Appdata ​
| Workflow | Type | Description |
|---|---|---|
| appdata.credential.create | Atomic | Create a read-only direct-connection credential (psql, DBeaver, Metabase) for an app |
| appdata.credential.ensure-app | Atomic | Ensure a writable AppHost/process credential on the app's own Postgres instance. Creates once; later calls rotate the password. |
| appdata.credential.list | Atomic | List an app's direct-connection credentials |
| appdata.credential.revoke | Atomic | Revoke a direct-connection credential, terminating its sessions |
| appdata.credential.rotate | Atomic | Rotate a direct-connection credential's password |
| appdata.instance.backup | Atomic | Dump the app's own Postgres instance (pg_dump -Fc on the host) |
| appdata.instance.ensure-app-owned-policies | Atomic | Apply owner-only write policies to an app's app-owned tables on its own instance; idempotent, and a no-op for apps on the shared plane |
| appdata.instance.ensure-system-tables | Atomic | Ensure an app's own instance carries the appdata audit trail and replay ledger; idempotent, and a no-op for apps on the shared plane |
| appdata.instance.migrate | Atomic | Move the app's serving data from the shared server to its own Postgres instance |
| appdata.instance.pause | Atomic | Stop the app's instance; its data stays and the next connection wakes it |
| appdata.instance.provision | Atomic | Provision the app's own Postgres instance on an appdata host (idempotent) |
| appdata.instance.restore | Atomic | Restore a dump from this app's instance onto a different app instance in the same organization; the source stays up |
| appdata.instance.resume | Atomic | Start the app's instance |
| appdata.instance.status | Atomic | Where the app's data lives and, for an instance, its live state |
| appdata.publish-as-app | Atomic | Publish an organization-side record into an app-owned appdata table, visible to every end-user of the app |
| appdata.query.delete | Atomic | Delete a saved query; its versions are kept and its name becomes free again |
| appdata.query.get | Atomic | Read one saved query, optionally with every earlier version of it |
| appdata.query.history | Atomic | List statements offered to the app's SQL endpoint, admitted or refused |
| appdata.query.list | Atomic | List saved queries and folders for an app, scoped to what the caller may see |
| appdata.query.save | Atomic | Save a named SQL statement for an app, private or shared with the organization |
| appdata.query.update | Atomic | Update a saved query; the previous text is kept as a version |
| appdata.retract-as-app | Atomic | Retract records an organization published into an app-owned appdata table |
| appdata.schema.introspect | Atomic | Read an app's live serving schema: relations, columns, indexes, constraints, policies, functions and sizes |
